1 results (0.002 seconds)

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

core/lib/upload/um-image-upload.php in the UltimateMember plugin 2.0 for WordPress has a cross-site scripting vulnerability because it fails to properly sanitize user input passed to the $temp variable. core/lib/upload/um-image-upload.php en el plugin UltimateMember 2.0 para WordPress tiene una vulnerabilidad de Cross-Site Scripting (XSS) debido a que fracasa a la hora de sanear las entradas del usuario que se pasan a la variable $temp. WordPress UltimateMember plugin version 2.0 suffers from multiple cross site scripting vulnerabilities. • https://packetstormsecurity.com/files/146403/WordPress-UltimateMember-2.0-Cross-Site-Scripting.html https://wpvulndb.com/vulnerabilities/9705 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •